Title: Reference leaks in `_hashlib.hmac_new` and `_hashlib.hmac_digest` · Issue #130151 · python/cpython · GitHub
Open Graph Title: Reference leaks in `_hashlib.hmac_new` and `_hashlib.hmac_digest` · Issue #130151 · python/cpython
X Title: Reference leaks in `_hashlib.hmac_new` and `_hashlib.hmac_digest` · Issue #130151 · python/cpython
Description: Bug report Bug description: The following leaks: def test_leak1(self): import _hashlib self.assertRaises(TypeError, _hashlib.hmac_new, b"key", 1, "sha256") The issue is in _hashlib_hmac_new_impl: self = PyObject_New(HMACobject, type); .....
Open Graph Description: Bug report Bug description: The following leaks: def test_leak1(self): import _hashlib self.assertRaises(TypeError, _hashlib.hmac_new, b"key", 1, "sha256") The issue is in _hashlib_hmac_new_impl: s...
X Description: Bug report Bug description: The following leaks: def test_leak1(self): import _hashlib self.assertRaises(TypeError, _hashlib.hmac_new, b"key", 1, "sha256") The issue is in _hash...
Opengraph URL: https://github.com/python/cpython/issues/130151
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Reference leaks in `_hashlib.hmac_new` and `_hashlib.hmac_digest`","articleBody":"# Bug report\n\n### Bug description:\n\nThe following leaks:\n\n```py\ndef test_leak1(self):\n import _hashlib\n self.assertRaises(TypeError, _hashlib.hmac_new, b\"key\", 1, \"sha256\")\n```\n\nThe issue is in `_hashlib_hmac_new_impl`:\n\n```c\n self = PyObject_New(HMACobject, type);\n ...\n if ((msg_obj != NULL) \u0026\u0026 (msg_obj != Py_None)) {\n if (!_hmac_update(self, msg_obj))\n goto error;\n }\n return (PyObject*)self;\n\nerror:\n if (ctx) HMAC_CTX_free(ctx);\n if (self) PyObject_Free(self);\n return NULL;\n```\n\nMore precisely, the issue is that we are only calling `PyObject_Free(self)` and we are not decrefing the type. So we need to call `Py_XDECREF(self);` instead and free `ctx` separately if `self` has not already been allocated. Note that the HMAC context is still cleared so we should not leak anything sensitive.\n\nThere is also a missing `HMAC_CTX_free` call in `_hmac_digest`, if the copy of the HMAC context fails. Again, there shouldn't be a security issue as the temporary context should still not be initialized on failure (and the secret key is not stored within, hopefully).\n\n### CPython versions tested on:\n\nCPython main branch\n\n### Operating systems tested on:\n\n_No response_\n\n\u003c!-- gh-linked-prs --\u003e\n### Linked PRs\n* gh-130152\n* gh-130491\n* gh-130539\n\u003c!-- /gh-linked-prs --\u003e\n","author":{"url":"https://github.com/picnixz","@type":"Person","name":"picnixz"},"datePublished":"2025-02-15T11:22:22.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/130151/cpython/issues/130151"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:30fa49ef-2374-ead7-eef3-6c4f07e9cbd4 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | B6BA:64491:9AC5BF:D7042D:696A78CB |
| html-safe-nonce | 94734b3631206dad249fbf7951ef9e869752bb1e74de1bb89721c4ceb8b1a692 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCNkJBOjY0NDkxOjlBQzVCRjpENzA0MkQ6Njk2QTc4Q0IiLCJ2aXNpdG9yX2lkIjoiODEzNTk3MzQ2NDE2MjU5NzA2NyIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | b383ab78e03c73cf61047372d7b65e0aa25e3fd05c2be185948a321e610f4b5b |
| hovercard-subject-tag | issue:2855415522 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python/cpython/130151/issue_layout |
| twitter:image | https://opengraph.githubassets.com/5e6f9a09f0c10fe0b7560088348e729990368f643031216b9bed4df4e2a09708/python/cpython/issues/130151 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/5e6f9a09f0c10fe0b7560088348e729990368f643031216b9bed4df4e2a09708/python/cpython/issues/130151 |
| og:image:alt | Bug report Bug description: The following leaks: def test_leak1(self): import _hashlib self.assertRaises(TypeError, _hashlib.hmac_new, b"key", 1, "sha256") The issue is in _hashlib_hmac_new_impl: s... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | picnixz |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5b774e44f85c14a75886edd04ddda4e5a25ddebbb241bcbb590b08a3048730e8 |
| turbo-cache-control | no-preview |
| go-import | github.com/python/cpython git https://github.com/python/cpython.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 81598961 |
| octolytics-dimension-repository_nwo | python/cpython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 81598961 |
| octolytics-dimension-repository_network_root_nwo | python/cpython |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | cc5f4eee261b3601c1e98e217ceaf28508b9567e |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width